Feb 15 2023 09:27 AM
Hello, I see that the Classic ATP (atp.azure.com) will be redirecting to the Security portal. However I'm curious about the Scheduled reports we have set up for Lateral movements and Summary. I don't see a direct correlation in the Security portal for those style of reports. What is the recommendation to schedule reports in the Security portal or at least setup within the Security portal to view?
Thank you,
Serge
Feb 16 2023 04:12 AM - edited Feb 16 2023 04:13 AM
A lateral movement path report is covered by the ISPM assessments. You can find more details here: https://learn.microsoft.com/en-us/defender-for-identity/security-assessment-riskiest-lmp
Regarding Summary report, the health issues are available in M365D Settings > Identities > Health issues, and a summary of alerts can be found by exporting the alerts queue or using Advanced Hunting (30 days of data).
As of now, the security.microsoft.com portal does not support Schedules reports. I'll be happy if you can contact me directly by mail (t-lshapira@microsoft.com) so I can further understand your needs.
Mar 02 2023 01:22 AM
There seems to be a few threads on a similar subject (new portal transition and losing "features"), so was not sure where to post in reply. @LiorShapira you seem happy to want the feedback...
The only scheduled report we use DAILY is the Modifications to sensitive groups, and if you think logically about that, it is a rational report that is useful on a schedule. MDI has seemingly good logic in what these are, and being informed by push notification is exceedingly important (be even better if we didn't get emailed when there are ZERO entries in there, but hey!)...one does not want to have to run an adhoc query to do that - it is a backward step. Currently, I think the suggestion as a "workaround" is to run the Advanced Hunting query and define the groups your are interested in - that is not workable at all. This alone would stop us moving to the new portal, as pathetic as that seems. FWIW, I actually like the new portal...just struggling to find things. I know there is a mapping table to show where things are...but it doesn't say what is missing or being thought about !
Mar 05 2023 05:53 AM - edited Mar 05 2023 05:54 AM
@StuartH . Thanks for your feedback, I appreciate it. We will take it into account and will make sure to update the documentation.
Mar 06 2023 02:14 AM
Mar 23 2023 08:37 AM
@LiorShapira, we utilized the weekly scheduled reports too and they stopped working when the MDI portal redirection was enabled.
Are there plans to migrate this functionality to security.microsoft.com or another portal? If not, I recommend adding some information to the emailed reports sharing the reports will be deprecated and steps to disable them. BTW, with the portal redirection is enabled, there is no way to disable the reports. If June 30th comes and the portal redirection is forced, there will be no way for people to disable the email reports and people will start putting in tickets if they are using the reports.
Mar 25 2023 07:53 AM
Mar 28 2023 05:32 AM
@josequintino I am a little stunned that Microsoft are just yanking [very used] features away, and think that is acceptable. I see the portal notice (saying Jan 31) is now replaced with July 31 - surely that is time enough to get a satisfactory solution in place ? Atleast expand on this and come up with something workable for all of your customers, and not making us do the work:
"To use the Microsoft Graph Security API:
1- Register an application in Azure AD and grant the necessary permissions.
2- Use the API to fetch alerts and related information from the Microsoft 365 Defender portal.
3- Create custom reports using the fetched data and schedule them to be sent via email or any other preferred method."
It just seems like you are dropping a lot of the good features that we purchased Azure ATP (MDI) for
Apr 02 2023 06:09 AM